CISA’s 17 Active Directory Attack Techniques: Detection and Defense with Sophos MDR

Фото: Zulfugar Karimov (Unsplash) — https://unsplash.com/photos/a-security-and-privacy-dashboard-with-its-status--nBClEqKKVM?utm_source=dev48&utm_medium=referral

Source: SOPHOS•

CISA’s 17 Active Directory Attack Techniques: Detection and Defense with Sophos MDR

Learn how to detect and mitigate CISA’s 17 most common Active Directory compromise techniques. Discover the identity security fundamentals, telemetry, and MDR strategies that help stop attackers before they reach privileged access.

This article is part of an ongoing series from Sophos frontline security operations specialists, sharing the expertise they use to strengthen our industry-leading Managed Detection and Response (MDR) service and defend customers against evolving AI-era threats.

A faster detection engine won’t help if the front door is still unlocked. Sophos’ 2025 Active Adversary Report found that attackers’ first attempt to breach Active Directory came within a median of 11 hours.

This article groups the 17 techniques identified by CISA and its government partners into four categories, showing how strong identity controls, useful telemetry, and MDR-led response work together when attackers abuse legitimate identity systems.

That urgency isn’t happening in a vacuum: AI is here to stay. Pandora’s box is open, and governments, companies leading the frontier models, and the cybersecurity industry are working together to establish responsible guardrails for how this technology is developed and used.

The practical reality for security teams is already here: AI is accelerating both defense and offense. Organizations can analyze data, investigate threats, and respond faster. Attackers can automate reconnaissance, generate tooling, and compress the time between initial access and impact. The Sophos AI Security 2026 Report makes the point: AI is compressing attack timelines, not inventing new attack types.

That acceleration makes identity fundamentals even more important. Microsoft Active Directory and Entra ID sit at the center of many on-premises and cloud environments, and attackers know that legitimate identity functions can take them from a foothold to privileged access.

As noted above, Sophos’ 2025 Active Adversary Report puts the median time between an attacker’s initial action and their first attempt to breach AD at just 11 hours — and AI may make that window smaller.

Rather than cover each of CISA’s 17 techniques individually, this review examines them through those four categories — the fundamentals defenders can apply, the telemetry that makes abuse visible, and how Sophos MDR helps detect, investigate, and respond.

The future of security will be increasingly agent-enabled, but the fundamentals remain nonnegotiable, and the four categories below start where most compromises still begin: credential access.

1. Credential access: Secure identities before attackers can use them

Techniques covered: Password spraying, Kerberoasting, AS-REP Roasting, and passwords in Group Policy Preferences.

Credential-access techniques turn ordinary identity functions into a route toward broader access. A password spray, a Kerberos service-ticket request, or a legacy credential becomes more concerning when it connects to discovery and movement on the endpoint or in the network.

The fundamental controls include:

  • Use phishing-resistant MFA for privileged users.
  • Eliminate unnecessary service accounts.
  • Use group Managed Service Accounts where possible.
  • Remove legacy credentials.
  • Ensure authentication events are centrally logged.

A recent Sophos Digital Forensics and Incident Response (DFIR) engagement shows how quickly this can develop. In March 2026, Sophos investigated an Interlock ransomware incident in which the attacker queried Active Directory for domain-group information and then queried service principal names, indicating a Kerberoasting attempt.

The activity was not an isolated event. It was part of a broader sequence that began with an endpoint compromise and progressed into domain discovery, credential access, and lateral movement activity.

MDR takeaway: Sophos MDR can correlate authentication activity with endpoint and directory signals, then investigate when the combined pattern points to credential abuse. The point is not to treat every Kerberos request as malicious; it is to determine when identity activity is contributing to an attack sequence and support timely response.

Why this matters: Credential attacks can look like normal authentication activity. In the Interlock investigation, the attacker used familiar tools and legitimate protocols. Strong fundamentals, complete endpoint coverage, appropriate authentication controls, and useful telemetry give defenders more opportunities to identify and interrupt the attack earlier.

How Sophos can help: Sophos MDR connects Microsoft identity, endpoint, and directory signals to help determine when authentication activity is part of a broader attack sequence. Sophos ITDR can add identity posture checks, leaked-credential monitoring, and identity-specific response capabilities where organizations need deeper identity visibility.

2. Privilege escalation and lateral movement: Protect the paths to Tier 0

Techniques covered: MachineAccountQuota compromise, unconstrained delegation, DCSync, dumping ntds.dit, and Shadow Credentials.

Once attackers obtain an initial identity, they look for ways to increase their access. They may create a new computer account, abuse delegation, replicate directory data, or modify sensitive attributes to move closer to domain administrator privileges.

The fundamental controls include:

  • Restrict who can create computer accounts.
  • Eliminate unnecessary delegation.
  • Minimize replication permissions.
  • Protect domain controllers.
  • Review access to sensitive directory attributes.

A Sophos MDR case documented in the 2025 Active Adversary Report shows why the path to Tier 0 deserves its own discussion. After initial access through an unpatched FortiGate VPN appliance, the attacker moved laterally to a domain controller, used AV-killer tools, performed enumeration, and established persistence on multiple devices. Sophos MDR disrupted the activity while the attack was still unfolding.

MDR takeaway: Put privileged access and directory changes under continuous monitoring. Sophos MDR can investigate account and computer-object creation, explicit-credential logons, privileged operations, directory changes, and replication activity alongside the originating account, source system, and related endpoint behavior when that telemetry is available.

Why this matters: Many of these actions can be legitimate. A new computer account, directory modification, or replication request becomes meaningful when considered alongside the account that made it, the source system, related logons, and activity on the target system. MDR helps evaluate those connections instead of treating every administrative event as malicious.

How Sophos can help: Sophos MDR helps investigate the activity surrounding privilege escalation, including unusual logons, new or modified computer objects, privileged operations, and related endpoint behavior. Sophos ITDR can add visibility into risky permissions and identity relationships that may expose paths toward Tier 0.

3. Certificates and authentication: Protect the systems that issue trust

Techniques covered: AD CS compromise, including Golden Certificate, Golden Ticket, and Silver Ticket.

Trust is issued by infrastructure. Certificate authorities, certificate templates, domain controllers, and Kerberos services decide which credentials appear valid. That makes changes to the systems that issue trust as important as the authentication events that follow them.

The fundamental controls include:

  • Secure certificate templates.
  • Restrict access to certificate authorities and domain controllers.
  • Protect certificate private keys and backups.
  • Remove unnecessary authentication permissions.
  • Use group Managed Service Accounts where appropriate.
  • Maintain rotation and recovery procedures for critical Kerberos and computer-account secrets.

Recent Sophos research on the STAC4749 campaign shows why trust infrastructure deserves attention. In several incidents, attackers used embedded certificate-authority certificates to pin their command-and-control communications, making the connection appear trusted to the malware. This was not an AD CS compromise, but it illustrates the underlying problem: certificate trust can be abused below the visible sign-in event.

Sophos’ 2026 reporting reinforces the same lesson from a different angle: it identifies Golden Ticket attacks as a high-impact identity threat and emphasizes correlating endpoint, identity, and network telemetry when investigating privilege escalation and lateral movement.

MDR takeaway: Monitor the systems that issue trust, not only the authentications that follow. Sophos MDR can investigate certificate requests and issuance, changes to certificate templates or CA security settings, unusual Kerberos ticket activity, and related PowerShell or process activity on certificate authorities and domain controllers when that telemetry is enabled and available.

Why this matters: A forged certificate or Kerberos ticket may look like a valid authentication event. The more useful signal may be the activity around it: a certificate-template change followed by a certificate request, unexpected administration on a certificate authority, and unusual commands on a domain controller. Centralized logging and correlation give defenders more opportunities to identify that sequence.

How Sophos can help: Sophos Next-Gen SIEM can bring additional certificate, authentication, and legacy-system telemetry into the investigation workflow used by Sophos MDR, where those sources are configured and available. That broader history helps analysts investigate suspicious trust and authentication activity.

4. Persistence and hybrid coverage: Assume one reset may not be enough

Techniques covered: Golden SAML, Microsoft Entra Connect compromise, one-way domain trust bypass, SID History compromise, and Skeleton Key.

The more an environment depends on connected identity systems, the more response has to account for those connections. A compromised credential, token, trust, synchronization path, or authentication component can keep the attacker’s access alive after the first artifact is removed.

In March 2025, a Sophos employee fell victim to a phishing attack that captured credentials and bypassed MFA. The attacker tried to move into Sophos’ network, but Sophos Labs, Managed Detection and Response, Internal Detection and Response, and IT teams shared telemetry and investigated the activity. The incident is not one of CISA’s named AD techniques; it demonstrates the response principle behind this category: identity recovery must account for more than the first compromised password.

Sophos’ 2026 reporting reinforces the same point. Sixty-seven percent of the intrusions studied began with compromised credentials or other identity-related tactics, including authentication-token theft and abused trusted relationships.

The fundamental controls include:

  • Protect Microsoft Entra Connect, AD FS, and domain controllers as Tier 0 systems.
  • Separate privileged AD and Entra ID accounts.
  • Restrict trust relationships.
  • Review SID History.
  • Harden LSASS and domain controllers.
  • Centrally log synchronization, federation, authentication, and administrative activity.

MDR takeaway: When identity activity is suspicious, investigate the surrounding sessions, endpoints, directory changes, and connected Microsoft 365 activity before closing the case. Sophos MDR’s Microsoft integrations can provide that operating context and, where authorized, support actions such as blocking sign-in or revoking sessions. Sophos ITDR can add ongoing visibility into identity posture and relationships across AD and Entra ID.

Why this matters: The response to a compromised Microsoft 365 identity may involve resetting credentials, terminating Entra ID tokens, revoking sessions, removing malicious inbox rules, or disabling an unauthorized application. The same principle applies to Active Directory: removing the initial artifact is one step. Defenders must also validate the underlying trust relationships, credentials, tokens, and authentication systems for persistent access.

How Sophos can help: Sophos MDR can support authorized Microsoft 365 response actions, such as blocking sign-in or revoking sessions, while giving analysts context across sign-ins, endpoints, and related users. Sophos ITDR can add ongoing visibility into identity posture and AD/Entra ID relationships that may need review during recovery.

Conclusion

CISA’s 17 techniques point back to the same operational question: when an attacker starts using legitimate identity functions, can the organization see the sequence and act before it reaches Tier 0?

The answer still depends on fundamentals: protected privileged access, hardened identity systems, useful telemetry, and response actions that are ready to use. AI can make MDR faster and more scalable, but it cannot lock the front door.

That foundation remains the organization’s first defense against a shrinking 11-hour window.

What this article says